CHRISTIE ÔÚ RANSOMHUB ¹¥»÷ºóÅû¶Êý¾Ýй¶Ê¼þ
Ðû²¼Ê±¼ä 2024-05-305ÔÂ28ÈÕ£¬ÀÕË÷Èí¼þ×éÖ¯ RansomHub Íþв鶱»µÁÊý¾Ýºó£¬ÅÄÂôÐмÑÊ¿µÃÅû¶ÁËÊý¾Ýй¶Ê¼þ¡£´Ë´ÎÄþ¾²Â©¶´·¢ÉúÓÚ±¾Ô³õ¡£¹¥»÷·¢Éúºó£¬¸ÃÅÄÂôÐеÄÍøÕ¾ÎÞ·¨·ÃÎÊ¡£¾Ý BBC ±¨µÀ£¬¼ÑÊ¿µÃÒòÍøÂç¹¥»÷ÎÞ·¨³öÊÛ¼ÛÖµÔ¼ 8.4 ÒÚÃÀÔªµÄÒÕÊõÆ·ºÍÆäËû¸ß¼ÛÖµÎïÆ·¡£´º¼¾ÅÄÂô»áÉÏ°üÂÞÒ»·ù¼ÛÖµ 3500 ÍòÃÀÔªµÄèó¸ß»×÷ºÍÕäÏ¡ÆÏÌѾƵÈÅÄÆ·¡£ÓÉÓÚÍøÂç¹¥»÷£¬Ò»Ð©ÏúÊÛ±»ÍƳ١£RansomHub Éù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬²¢½«¸Ã¹«Ë¾Ìí¼Óµ½Æä Tor й©ÍøÕ¾¡£¸ÃÀÕË÷×éÖ¯³Æ£¬ËûÃÇÇÔÈ¡ÁË 2GB µÄÃô¸ÐÐÅÏ¢£¬ÆäÖаüÂÞÖÁÉÙ 50 ÍòÃû¼ÑÊ¿µÃ¿Í»§µÄ¸öÈËÐÅÏ¢¡£¸Ã×éÖ¯ÌåÏÖ£ºÍ¨¹ý·ÃÎʼÑÊ¿µÃµÄÍøÂ磬ÎÒÃÇÄܹ»»ñÈ¡Æä¿Í»§µÄÃô¸Ð¸öÈËÐÅÏ¢£¬°üÂÞ [³öÉúµØ¡¢MRZ¡¢ÍêÕûÎļþºÅ¡¢³öÉúÈÕÆÚ¡¢µ½ÆÚÈÕÆÚ¡¢Ãû×Ö¡¢ÐÕÊÏ¡¢¿¯ÐÐÈÕÆÚ¡¢¿¯Ðлú¹¹¡¢ÐÔ±ð¡¢ÎļþÀà±ð¡¢ÎļþÀàÐÍ¡¢¹ú¼®Ãû³Æ]£¬ÒÔ¼°À´×ÔÊÀ½ç¸÷µØµÄÖÁÉÙ 50 ÍòÃû˽ÈË¿Í»§µÄµØÖ·¡¢Éí¸ß¡¢ÖÖ×åµÈ¸ü¶àÃô¸ÐÐÅÏ¢¡£
https://securityaffairs.com/163808/cyber-crime/christie-data-breach.html
2. Google Play³¬90¸ö¶ñÒâÓ¦Ó㬰²×°Á¿´ï550Íò´Î
5ÔÂ28ÈÕ£¬ÓÐÁè¼Ý 90 ¸ö¶ñÒâ Android Ó¦Ó÷¨Ê½Í¨¹ý Google Play ±»°²×°Áè¼Ý 550 Íò´Î£¬ÓÃÓÚÁ÷´«¶ñÒâÈí¼þºÍ¹ã¸æÈí¼þ£¬¶ø Anatsa ÒøÐÐľÂí×î½üµÄ»î¶¯Á¿¼¤Ôö¡£Anatsa£¨ÓÖÃû¡°Teabot¡±£©ÊÇÒ»ÖÖÒøÐÐľÂí£¬Õë¶ÔÅ·ÖÞ¡¢ÃÀ¹ú¡¢Ó¢¹úºÍÑÇÖÞµÄ 650 ¶à¸ö½ðÈÚ»ú¹¹µÄÓ¦Ó÷¨Ê½¡£ËüÊÔͼÇÔÈ¡ÈËÃǵĵç×ÓÒøÐÐƾ֤ÒÔ½øÐÐÆÛÕ©½»Òס£2024 Äê 2 Ô£¬Threat Fabric ³ÂË߳ƣ¬×ÔÈ¥ÄêÄêµ×ÒÔÀ´£¬Anatsa ʹÓÃÉú²úÁ¦Èí¼þÀà±ðÖеÄÖÖÖÖÓÕ¶üÓ¦Ó÷¨Ê½Í¨¹ý Google Play ʵÏÖÁËÖÁÉÙ 150,000 ´ÎѬȾ¡£Zscaler ³ÂË߳ƣ¬ÔÚ¹ýÈ¥¼¸¸öÔÂÖУ¬Ëü»¹ÔÚ Google Play ÉÏ·¢ÏÖÁËÁè¼Ý 90 ¸ö¶ñÒâÓ¦Ó÷¨Ê½£¬ÕâЩӦÓ÷¨Ê½×ܹ²±»°²×°ÁË 550 Íò´Î¡£´ó¶àÊý¶ñÒâÓ¦Ó÷¨Ê½Ä£·Â¹¤¾ß¡¢¸öÐÔ»¯Ó¦Ó÷¨Ê½¡¢ÉãӰʵÓ÷¨Ê½¡¢Éú²úÁ¦ÒÔ¼°½¡¿µºÍ½¡ÉíÓ¦Ó÷¨Ê½¡£Õ¼¾ÝÖ÷µ¼Ö°Î»µÄÎå¸ö¶ñÒâÈí¼þ¼Ò×åÊÇ Joker¡¢Facestealer¡¢Anatsa¡¢Coper ºÍÖÖÖÖ¹ã¸æÈí¼þ¡£
https://www.bleepingcomputer.com/news/security/over-90-malicious-android-apps-with-55m-installs-found-on-google-play/
3. ½©Ê¬ÍøÂçCatDDOS ´ó·ùÔö¼Ó DDoS ¹¥»÷»î¶¯
5ÔÂ28ÈÕ£¬Ñо¿ÈËÔ±·¢ÏÖ£¬Mirai ÂþÑÜʽ¾Ü¾ø·þÎñ (DDoS) ½©Ê¬ÍøÂç±äÖÖ CatDDoS µÄ»î¶¯½üÆÚ¼¤Ôö¡£´Ë´Î¹¥»÷Õë¶ÔµÄÊǶà¸öÐÐÒµµÄ×éÖ¯£¬°üÂÞÃÀ¹ú¡¢·¨¹ú¡¢µÂ¹ú¡¢°ÍÎ÷ºÍÖйúµÄÔƹ©Ó¦ÉÌ¡¢Í¨ÐÅÌṩÉÌ¡¢½¨Öþ¹«Ë¾¡¢¿ÆÑÐʵÌåºÍ½ÌÓý»ú¹¹¡£¸Ã¶ñÒâÈí¼þÓÚÈ¥Äê 8 ÔÂÊ״ηºÆ𣬲¢ÔÚ 2023 Äê 9 Ô³ÉΪһÖÖÏà¶ÔÆÕ±éµÄÍþв¡£CatDDoS ÔÚ 12 Ô»ù±¾Ïûʧ£¬´ÙʹÖйúÆæ°²ÐÅ XLab ¸ú×ÙÍþвµÄÑо¿ÈËÔ±ÈÏΪ£¬¸Ã¶ñÒâÈí¼þµÄÔËÓªÕß¿ÉÄÜÒѾֹͣÁ˹¥»÷¡£CatDDoS ±£»¤Ï±»ÀûÓõÄ©¶´Ó°ÏìÁËÊýÊ®ÖÖ²úÎïºÍ¼¼Êõ£¬°üÂÞApache ActiveMQ ·þÎñÆ÷¡¢Apache Log4j¡¢Cisco Linksys¡¢Jenkins·þÎñÆ÷ºÍ NetGear ·ÓÉÆ÷¡£
https://www.darkreading.com/cyberattacks-data-breaches/catddos-threat-groups-sharply-ramp-up-ddos-attacks
4. »¥ÁªÍøµµ°¸¹ÝºÍ Wayback Machine ÔâÊÜ DDoS ÍøÂç¹¥»÷
5ÔÂ28ÈÕ£¬»¥ÁªÍøµµ°¸¹ÝÊÇÒ»¼Ò·ÇÓªÀûÐÔÑо¿Í¼Êé¹Ý£¬¹Ý²ØÓÐÊý°ÙÍò·ÝÀúÊ·Îļþ¡¢Éú´æµÄÍøÕ¾ºÍýÌåÄÚÈÝ£¬Ä¿Ç°Õý´¦ÓÚµÖÓù¼äЪÐÔ DDoS£¨ÂþÑÜʽ¾Ü¾ø·þÎñ£©ÍøÂç¹¥»÷µÄµÚÈýÌì¡£¾ÝͼÊé¹ÝÊÂÇéÈËÔ±³Æ£¬²ØÆ·ÊÇÄþ¾²µÄ£¬¾¡¹Ü·þÎñÈÔÈ»²»Îȶ¨¡£»¥ÁªÍøµµ°¸¹Ý Wayback Machine£¨Éú´æÁËÁè¼Ý 8660 ÒÚ¸öÍøÒ³µÄÀúÊ·¼Ç¼£©µÄ·ÃÎÊÒ²Êܵ½ÁËÓ°Ïì¡£×ÔÖÜÈÕ¹¥»÷¿ªÊ¼ÒÔÀ´£¬DDoS ÈëÇÖÿÃëÌᳫÊýÍò¸öÐé¼ÙÐÅÏ¢ÇëÇó¡£¹¥»÷À´Ô´Éв»Çå³þ¡£³ýÁË×î½üÔâÊܵÄÒ»²¨ÍøÂç¹¥»÷Ö®Í⣬»¥ÁªÍøµµ°¸¹Ý»¹Ôâµ½ÃÀ¹úͼÊé³öÊéÒµºÍÃÀ¹ú³ªÆ¬ÒµÐ»áµÄÆðËߣ¬ËûÃÇÉù³Æ»¥ÁªÍøµµ°¸¹ÝÇÖ·¸ÁËÆä°æȨ£¬²¢ÒªÇóÅâ³¥ÊýÒÚÃÀÔª²¢¼õÉÙËùÓÐͼÊé¹ÝµÄ·þÎñ¡£
https://blog.archive.org/2024/05/28/internet-archive-and-the-wayback-machine-under-ddos-cyber-attack/
5. Î÷ÑÅͼ¹«¹²Í¼Êé¹ÝÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÔÚÏßϵͳ̱»¾
5ÔÂ29ÈÕ£¬Î÷ÑÅͼ¹«¹²Í¼Êé¹ÝÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÆä·þÎñÏÝÈë̱»¾¡ª¡ªÎÞÏßÍøÂç¡¢Ô±¹¤ºÍÖ÷¹ËʹÓõļÆËã»úÒÔ¼°Õû¸öÔÚÏßĿ¼¶¼Ì±»¾ÁË¡£¸Ã×éÖ¯ÔÚÖÜÒ»ÏÂÎçµÄÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬Ê¼þ·¢ÉúÔÚÖÜÁù¡£¸ÃͼÊé¹ÝÓÐ 27 ¸ö²îÒìµÄ·Ö¹Ý£¬Îª½ü 80 Íò¾ÓÃñÌṩ·þÎñ¡£¸ÃͼÊé¹ÝÔ±¾¼Æ»®ÔÚÕóÍö½«Ê¿¼ÍÄîÈÕÖÜÄ©ÆÚ¼äÈÃϵͳÏÂÏßÒÔ¶Ô·þÎñÆ÷½øÐÐά»¤£¬µ«µ±ÌìÔçÉÏÈ´·¢ÏÖÁËÀÕË÷Èí¼þ¹¥»÷¡£ÔÚÊÓ²ìʼþµÄͬʱ£¬¸Ã¹«Ë¾ÒѹرÕËùÓÐϵͳ²¢ÁªÏµÁËÖ´·¨²¿ÃÅ¡£Ä¿Ç°Éв»Çå³þ»Ö¸´Ê±¼ä¡£Í¼Êé¹ÝÈÔ½«¿ª·Å£¬²¢½«ÊÖ¶¯½è³öÊé¼®ºÍ CD¡£Î÷ÑÅͼ¹«¹²Í¼Êé¹ÝÓëÈ«Çò¶à¸ö¶¼ÊкÍÏØͼÊé¹ÝϵͳһÑù£¬³ÉΪÀÕË÷Èí¼þÍÅ»ïµÄÄ¿±ê¡ª¡ªÕâЩÍÅ»ïÀûÓöԵç×ÓÊéºÍÒªº¦·þÎñµÄÐèÇó×÷Ϊ½è¿Ú£¬ÈÃÄ¿±êÖ§¸¶Êê½ð¡£
https://therecord.media/ransomware-attack-seattle-knocks-out
6. ÃÀ¹úÕþ¸®¶Ô911 S5½©Ê¬ÍøÂç±³ºóµÄ·¸×ïÍÅ»ïʵʩÖƲÃ
5ÔÂ28ÈÕ£¬¼ÓÄôóÉ᲼³¿Ë´óѧµÄÑо¿ÈËÔ±ÔÚԼĪÁ½ÄêÇ°£¨2022 Äê 6 Ô£©Í¸Â¶£¬ÕâÖÖ·Ç·¨×¡Õ¬ÊðÀí·þÎñͨ¹ýÌṩÃâ·Ñ VPN ·þÎñÀ´ÒýÓÕDZÔÚÊܺ¦Õß°²×°¶ñÒâÈí¼þ£¬Ö¼ÔÚ½«ËûÃÇµÄ IP µØÖ·Ìí¼Óµ½ 911 S5 ½©Ê¬ÍøÂçÖС£Æäʱ£¬½©Ê¬ÍøÂç¿ØÖÆ×ÅÀ´×ÔÊÀ½ç¸÷µØµÄԼĪ 120,000 ¸öסլÊðÀí½Úµã£¬ËùÓнڵ㶼ÓëλÓÚº£Íâ»òÍйÜÔÚÔÆ·þÎñÆ÷ÄڵĶà¸öÃüÁîºÍ¿ØÖÆ·þÎñÆ÷½øÐÐͨÐÅ¡£911 S5 ÒòÄþ¾²Â©¶´¶ø¡°Í߽⡱£¬ÆäÒµÎñÔËÓªµÄÒªº¦×é¼þ±»´Ý»Ù¡£Ò»µ©ÍøÂç·¸×ï·Ö×Óͨ¹ý 911 S5 ½©Ê¬ÍøÂçÑÚ¸ÇÁËËûÃǵÄÊý×Ö×Ù¼££¬ËûÃǵÄÍøÂç·¸×ïËƺõ¾Í»á×·Ëݵ½Êܺ¦ÕߵļÆËã»ú¶ø²»ÊÇËûÃÇ×Ô¼ºµÄ¼ÆËã»ú¡£OFAC Ôö²¹Ëµ£¬×¡Õ¬ÊðÀí½©Ê¬ÍøÂçÈëÇÖÁËԼĪ 1900 Íò¸ö IP µØÖ·¡£ÕâЩÊÜѬȾµÄÉ豸ÔÊÐíÍøÂç·¸×ï·Ö×ÓÌá½»ÊýÍò·ÝÓë¹Ú×´²¡¶¾Ô®Öú¡¢¾È¼ÃºÍ¾¼ÃÄþ¾²·¨°¸Ïà¹ØµÄ¼Æ»®µÄÆÛÕ©ÐÔÉêÇ룬Ôì³ÉÊýÊ®ÒÚÃÀÔªµÄËðʧ¡£
https://www.bleepingcomputer.com/news/security/us-govt-sanctions-cybercrime-gang-behind-massive-911-s5-proxy-botnet-linked-to-illegitimate-residential-proxy-service/